ModSecurity is a web application firewall used to block suspicious web requests before they reach an application such as WordPress. It helps protect websites from common attacks, but it can occasionally block legitimate actions if a request looks suspicious.
What ModSecurity protects against
- SQL injection attempts.
- Cross-site scripting attempts.
- Malicious upload attempts.
- Known exploit patterns.
- Suspicious request behaviour.
False positives
Sometimes ModSecurity blocks a legitimate admin action, such as saving a WordPress page, submitting a form or uploading content. This is called a false positive.
What support needs
If you think ModSecurity is blocking something, provide the page URL, exact time, your IP address and what action you were taking. This helps us find the matching security rule in logs.
Best practice
Do not disable ModSecurity globally unless absolutely necessary. It is usually better to tune or whitelist a specific rule for a specific account or request.
Need help?
Open a support ticket directly from within your GetHosting.online customer account. Phone support is also welcome on (+44) 01457 337 247. For international contact numbers, please see our contact page.
GETHOSTING.ONLINE is a subsidiary of GetUK Support.